DigiCert KnowledgeBase - Technical Support-hero

Knowledge Base

Create a .pem File for TLS/SSL Certificate Installations

Solution ID : TL27
Last Modified : 05/31/2024

.pem TLS/SSL Creation Instructions

SSL .pem files (concatenated certificate container files), are frequently required for certificate installations when multiple certificates are being imported as one file.

This article contains multiple sets of instructions that walk through various .pem file creation scenarios for certificate installation.

  • Create a .pem file with the Entire TLS/SSL Certificate Trust Chain
  • Create a .pem file with the TLS/SSL Server and Intermediate Certificates
  • Create a .pem with the Private Key and Entire Trust Chain

SECURE UP TO 250 SUBDOMAINS WITH A DIGICERT WILDCARD TLS/SSL CERTIFICATE.

Create a .pem file with the Entire TLS/SSL Certificate Trust Chain

  1. In your CertCentral account, on the certificate's order details page, download your Intermediate (DigiCertCA.crt), Root (TrustedRoot.crt), and Primary Certificates (your_domain_name.crt).

    See Download a TLS/SSL certificate from your CertCentral account

  2. Open a text editor (such as Notepad) and paste the entire body of each certificate into one text file in the following order:
    1. Primary Certificate - your_domain_name.crt
    2. Intermediate Certificate - DigiCertCA.crt
    3. Root Certificate - TrustedRoot.crt

      Note: Some servers may require you to add the certificates in the reverse order in the .pem file:

      1. Root Certificate
      2. Intermediate Certificate
      3. Primary Certificate

       
  3. Make sure to include the beginning and end tags on each certificate. The result should look like this:

     

    -----BEGIN CERTIFICATE-----
    Your Primary TLS/SSL certificate: your_domain_name.crt
    -----END CERTIFICATE-----

    -----BEGIN CERTIFICATE-----
    Your Intermediate certificate: DigiCertCA.crt
    -----END CERTIFICATE-----

    -----BEGIN CERTIFICATE-----
    Your Root certificate: TrustedRoot.crt
    -----END CERTIFICATE-----

     


  4. Save the combined file as your_domain_name.pem.
    The .pem file is now ready to use.


Create a .pem file with the TLS/SSL Server and Intermediate Certificates

  1. In your CertCentral account, on the certificate's order details page, download your Intermediate (DigiCertCA.crt) and Primary Certificates (your_domain_name.crt).

    See Download a TLS/SSL certificate from your CertCentral account

  2. Open a text editor (such as Notepad) and paste the entire body of each certificate into one text file in the following order:
    1. The Primary Certificate - your_domain_name.crt
    2. The Intermediate Certificate - DigiCertCA.crt
  3. Make sure to include the beginning and end tags on each certificate. The result should look like this:

    -----BEGIN CERTIFICATE-----
    Your Primary TLS/SSL certificate: your_domain_name.crt
    -----END CERTIFICATE-----

    -----BEGIN CERTIFICATE-----
    Your Intermediate certificate: DigiCertCA.crt
    -----END CERTIFICATE-----


  4. Save the combined file as your_domain_name.pem.
    The .pem file is now ready to use.


Create a .pem with the Private Key and Entire Trust Chain

  1. In your CertCentral account, on the certificate's order details page, download your Intermediate (DigiCertCA.crt), Root (TrustedRoot.crt), and Primary Certificates (your_domain_name.crt).

    See Download a TLS/SSL certificate from your CertCentral account

  2. Open a text editor (such as Notepad) and paste the entire body of each certificate into one text file in the following order:
    1. The Private Key - your_domain_name.key
    2. The Primary Certificate - your_domain_name.crt
    3. The Intermediate Certificate - DigiCertCA.crt
    4. The Root Certificate - TrustedRoot.crt
  3. Make sure to include the beginning and end tags on each certificate. The result should look like this:

    -----BEGIN RSA PRIVATE KEY-----
    Your Private Key: your_domain_name.key
    -----END RSA PRIVATE KEY-----

    -----BEGIN CERTIFICATE-----
    Your Primary TLS/SSL certificate: your_domain_name.crt
    -----END CERTIFICATE-----

    -----BEGIN CERTIFICATE-----
    Your Intermediate certificate: DigiCertCA.crt
    -----END CERTIFICATE-----

    -----BEGIN CERTIFICATE-----
    Your Root certificate: TrustedRoot.crt
    -----END CERTIFICATE-----


  4. Save the combined file as your_domain_name.pem.
    The .pem file is now ready to use.